Certified Information Security Manager (CISM)Information Security Risk ManagementMedium
A CISO is tasked with improving the organization's information security posture. They observe that security incidents are often discovered reactively, leading to significant disruption and recovery costs. Which of the following approaches would BEST help the CISO shift from a reactive to a proactive security stance?
- AUpgrading all network firewalls to next-generation models with advanced intrusion prevention.
- BEstablishing a continuous threat hunting program to identify advanced persistent threats (APTs).
- CIncreasing the budget for security awareness training for all employees.
- DImplementing a more robust incident response plan with faster recovery objectives.
Show answer & explanationAnswer & explanation
Correct answer: B. Establishing a continuous threat hunting program to identify advanced persistent threats (APTs).
A continuous threat hunting program involves actively searching for threats that have bypassed existing security controls, enabling proactive identification and mitigation before they cause significant damage. This directly addresses the reactive nature of current incident discovery.
Why the other options are wrong
- A. This is a defensive control improvement but does not intrinsically involve proactive searching for threats already within the network.
- C. While important, security awareness training primarily addresses human-centric vulnerabilities and is not a direct proactive threat discovery mechanism.
- D. This improves reactivity but does not shift to a proactive stance in threat discovery.
Threat Hunting
Threat hunting is a proactive cybersecurity activity that involves iteratively and proactively searching for and detecting threats that are lurking undetected in a network.
- Focuses on finding unknown or advanced threats.
- Goes beyond automated security alerts.
- Requires skilled analysts and specialized tools.
Memory trick: To be proactive, you must hunt the shadows before they strike.